BULLETIN №082Last updated · 29 Jul 2026
Fine Tracker.
A public register of regulatory fines issued under EU compliance directives. Updated as decisions are published by national supervisory authorities.
5,273 entries
- Total fines
- €8.6bn
- Decisions
- 5,273
- Jurisdictions
- 33
- Regulators
- 74
- Avg monthly
- €162.7m
- YoY volume
- -21%
| Imposed | Company | Country | Authority | Type | Amount | ↗ |
|---|---|---|---|---|---|---|
| 12 May 2022 | Zito Auto di Gianfranco ZitoThe company was fined for operating a video surveillance system that did not meet the information requirements under GDPR Article 13 and Article 114 of the Italian Privacy Code. The authority found that the required notices for monitored individuals were not properly provided. | IT | Garante | GDPR | €3,000 | ↗ |
| 16 May 2012 | CONFORAMA ESPAÑA S.A.CONFORAMA ESPAÑA S.A. was fined by the AEPD in the amount of 3,000 EUR for sending unsolicited advertising SMS messages to customers. The conduct breached Article 21 of the LSSI on marketing communications without prior consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 16 Nov 2022 | Raiffeisen Bank SARaiffeisen Bank SA was fined EUR 3,000 by ANSPDCP for GDPR violations related to data security incidents. The case concerned shortcomings in the protection of personal data and the handling of security events. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 18 Jun 2025 | SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE SUR CATALOGUE GENERAL (procédure simplifiée)The CNIL imposed an administrative fine of 3,000 EUR on SOCIETE AYANT POUR ACTIVITE LA VENTE A DISTANCE SUR CATALOGUE GENERAL. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €3,000 | ↗ |
| 31 Jan 2023 | PRESTAMER, S.L.PRESTAMER, S.L. sent an email to 472 recipients without using BCC, which exposed recipients’ personal data. The AEPD imposed a 3,000 EUR fine for breaching data protection rules. | ES | AEPD | GDPR | €3,000 | ↗ |
| 16 Dec 2022 | NORDETIA CLINICS IBERIA, S.L.NORDETIA CLINICS IBERIA, S.L. was fined 3,000 EUR by the AEPD. The authority found that the company obstructed an inspection by failing to provide access required under Article 58(1) GDPR. | ES | AEPD | GDPR | €3,000 | ↗ |
| 23 Mar 2023 | Tehnoplus Industry SRLANSPDCP imposed a fine of EUR 3,000 on Tehnoplus Industry SRL for violating GDPR provisions. The case concerned non-compliance with personal data protection requirements. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 22 Jan 2022 | SOCIETE D'ENTRETIEN ET DE REPARATION DE VEHICULES AUTOMOBILESCNIL imposed a fine of 3,000 EUR on SOCIETE D'ENTRETIEN ET DE REPARATION DE VEHICULES AUTOMOBILES and issued an injunction under penalty. The case concerns a confirmed compliance breach. | FR | CNIL | GDPR | €3,000 | ↗ |
| 20 Feb 2021 | FLEXOGRÁFICA DEL MEDITERRÁNEO, S.L.The company was fined by the AEPD for failing to provide a privacy policy and cookie management on its websites. The authority also found that user consent was collected in a generic manner, which did not meet data protection requirements. | ES | AEPD | GDPR | €3,000 | ↗ |
| 16 Sept 2024 | Vodafone România SAVodafone România SA was fined EUR 3,000 by ANSPDCP. The authority found that the company failed to respond to a request to exercise the GDPR rights of access and erasure. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 12 Jul 2024 | CLIDEA DESARROLLO, S.A.CLIDEA DESARROLLO, S.A. was fined by the AEPD 3,000 EUR for sending an email to 349 recipients without using the BCC field. This exposed the personal email addresses of all recipients. | ES | AEPD | GDPR | €3,000 | ↗ |
| 11 Sept 2025 | MEDECIN GENERALISTE (procédure simplifiée)CNIL imposed an administrative fine of 3,000 EUR on MEDECIN GENERALISTE and issued an injunction. The case was handled under a simplified procedure. | FR | CNIL | GDPR | €3,000 | ↗ |
| 24 Jun 2020 | MIGUEL IBÁÑEZ BEZANILLA S.L.The entity was fined for failing to implement adequate security measures on its website and for providing insufficient privacy policy information. Non-compliance with cookie policy requirements was also identified. | ES | AEPD | GDPR | €3,000 | ↗ |
| 06 Mar 2023 | Integral Collection SRLIntegral Collection SRL was fined EUR 3,000 by ANSPDCP after a ransomware incident. The attack led to unauthorized access and loss of integrity and availability of personal data. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 26 Feb 2024 | VESTAS CEU ROMÂNIA SRLThe company was fined EUR 3,000 by ANSPDCP for unauthorized disclosure of personal data. The breach included names, place of residence, salary, and CV details. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 13 Feb 2015 | COMERCIAL POLINDUS, 21, S.L.COMERCIAL POLINDUS, 21, S.L. was fined by the AEPD 3,000 EUR for sending unsolicited commercial communications. The case concerned Article 21 of the LSSI, which prohibits such messages without prior recipient consent. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 18 Aug 2025 | SC Elite Conta SRLThe National Supervisory Authority for Personal Data Processing completed an investigation in July 2025 at SC Elite Conta SRL and found a GDPR violation. The company was fined for failing to properly notify a personal data security breach. | RO | ANSPDCP | GDPR | €3,000 | ↗ |
| 10 Sept 2021 | LODEJU, S.L.LODEJU, S.L. was fined EUR 3,000 by the AEPD for excessive video surveillance of public space without proper signage. The authority found a breach of GDPR Articles 5(1)(c) and 13. | ES | AEPD | GDPR | €3,000 | ↗ |
| 11 Dec 2015 | EAE INSTITUCION SUPERIOR DE FORMACION UNIVERSITARIA S.L.EAE INSTITUCION SUPERIOR DE FORMACION UNIVERSITARIA S.L. was fined by the AEPD EUR 3,000 for sending commercial emails without the required consent. The authority found this conduct breached Article 21.2 of the LSSI. | ES | AEPD | ePrivacy | €3,000 | ↗ |
| 27 Dec 2022 | Kaufland România SCSKaufland România SCS was fined by ANSPDCP EUR 3,000 for GDPR violations. The investigation was completed in November 2022. | RO | ANSPDCP | GDPR | €3,000 | ↗ |